Latest Vulnerabilities with Public Exploits

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

346,417 CVEs tracked 53,633 with exploits 4,859 exploited in wild 1,583 CISA KEV 4,077 Nuclei templates 52,306 vendors 43,872 researchers
53,633 results Clear all
CVE-2025-66736 7.1 HIGH 1 PoC EPSS 0.00
youlai-boot V2.21.1 - Auth Bypass
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.
CWE-284 Dec 22, 2025
CVE-2025-66735 7.5 HIGH 1 PoC EPSS 0.00
youlai-boot 2.21.1 - Privilege Escalation
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.
CWE-284 Dec 22, 2025
CVE-2025-14673 7.3 HIGH 1 PoC 1 Writeup EPSS 0.00
Gmg137 Snap7-rs < 1.142.1 - Memory Corruption
A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-122 Dec 14, 2025
CVE-2025-14672 7.3 HIGH 1 PoC 1 Writeup EPSS 0.00
Gmg137 Snap7-rs < 1.142.1 - Memory Corruption
A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
CWE-122 Dec 14, 2025
CVE-2025-14538 3.5 LOW 1 PoC EPSS 0.00
yangshare warehouseManager 1.1.0 - XSS
A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CWE-79 Dec 11, 2025
CVE-2025-55471 7.5 HIGH 1 PoC EPSS 0.00
youlai-boot <2.21.1 - Info Disclosure
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.
CWE-284 Nov 26, 2025
CVE-2025-55469 9.8 CRITICAL 1 PoC EPSS 0.00
youlai-boot <2.21.1 - Privilege Escalation
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.
CWE-284 Nov 26, 2025
CVE-2025-46175 7.5 HIGH 1 PoC EPSS 0.00
Ruoyi - Missing Authorization
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
CWE-284 Nov 26, 2025
CVE-2025-56396 8.8 HIGH 1 PoC EPSS 0.00
Ruoyi - Improper Access Control
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
CWE-284 Nov 26, 2025
CVE-2025-46174 7.5 HIGH 1 PoC EPSS 0.00
Ruoyi - Missing Authorization
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.
CWE-284 Nov 26, 2025
CVE-2025-10993 4.7 MEDIUM 1 PoC EPSS 0.00
MuYuCMS <2.7 - Code Injection
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the component Template Management. The manipulation results in code injection. It is possible to launch the attack remotely.
CWE-74 Sep 26, 2025
CVE-2025-56304 6.1 MEDIUM 1 PoC Analysis EPSS 0.00
Yzmcms < 7.3 - XSS
Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
CWE-79 Sep 23, 2025
CVE-2025-10787 6.3 MEDIUM 1 PoC EPSS 0.00
MuYuCMS <2.7 - SSRF
A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the component Add Fiend Link Handler. Performing manipulation of the argument Link URL results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used.
CWE-918 Sep 22, 2025
CVE-2025-55849 8.4 HIGH 1 PoC EPSS 0.00
WeiPHP <5.0 - SQL Injection
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CWE-89 Sep 08, 2025
CVE-2025-50902 8.8 HIGH 1 PoC EPSS 0.00
old-peanut Open-Shop <1.0.0 - CSRF
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.
CWE-352 Aug 20, 2025
CVE-2025-5680 6.3 MEDIUM 1 PoC EPSS 0.01
Tongzhouyun Agilebpm < 2.5.0 - Insecure Deserialization
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-502 Jun 05, 2025
CVE-2025-5679 6.3 MEDIUM 1 PoC EPSS 0.01
Tongzhouyun Agilebpm < 2.5.0 - Insecure Deserialization
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStrByFreeMarker of the file /src/main/java/com/dstz/sys/rest/controller/SysToolsController.java. The manipulation of the argument str leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-502 Jun 05, 2025
CVE-2025-5569 6.3 MEDIUM 2 PoCs NUCLEI EPSS 0.01
IdeaCMS <1.8 - SQL Injection
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.8 is able to address this issue. The patch is named 935aceb4c21338633de6d41e13332f7b9db4fa6a. It is recommended to upgrade the affected component.
CWE-74 Jun 04, 2025
CVE-2025-5523 3.5 LOW 1 PoC EPSS 0.00
enilu web-flash 1.0 - XSS
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-94 Jun 03, 2025
CVE-2025-5522 7.3 HIGH 1 PoC EPSS 0.00
bskms 蓝天幼儿园管理系统 - Auth Bypass
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-266 Jun 03, 2025